CVE-2018-12026
Phusion Passenger SpawningKit Contains Arbitrary Read/Write Vulnerability
9.8
CRITICAL
CVSS 3.1
EPSS 1.1%
Description
During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks. This then could result in arbitrary reads and writes, which in turn can result in information disclosure and privilege escalation.
How to fix CVE-2018-12026
To remediate CVE-2018-12026, upgrade the affected package to a fixed version below.
- —upgrade to 5.3.2 or later
Is CVE-2018-12026 being exploited?
Low — EPSS is 1.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 5.3.0, < 5.3.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |